25 / 33Third-Party Risk Management

Third party risk management, including your vendors' vendors

Third party risk management for Canadian organisations, covering the subcontractors and concentration B-10 asks about.

  • CCIE Security-led vendor reviews
  • OSFI B-10 expectations mapped
  • Canadian data residency
THE WORK

Third party risk management, three pillars, one operator.

One Canadian team lists your vendors, ranks them, and checks what they claim. Supply chain risk is the same problem one layer out, and it is where concentration hides.

  1. 1

    Inventory and criticality

    Every third party, what it touches, and which ones could stop your business if they stopped.

  2. 2

    Answers checked, not collected

    Questionnaire responses tested against evidence, and the gaps written into the contract at renewal.

  3. 3

    Fourth parties and concentration

    Who your critical vendors depend on, and where several of yours share one provider.

THE PROOF

Built to last. Evidence over promises.

OSFI B-10 makes you responsible for your vendors' subcontractors. Most registers stop at the vendor.

IN PRODUCTION

A register a Canadian regulator could read.

We had ninety-one vendors on a spreadsheet and no idea which mattered. SMEnode ranked them, and the uncomfortable finding was that four of our critical ones all ran on the same hosting provider. Nobody had asked. That single answer changed our continuity plan.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Third party risk management in Canada, made real.

Most programmes collect questionnaires and call it assurance. A completed questionnaire proves somebody typed.

The ranking is what makes the rest affordable.

Good work starts with an inventory and a hard ranking, because you cannot treat ninety vendors the same way and nobody has the budget to try. The question that does the sorting is simple: if this one stopped tomorrow, what stops with it? A handful will be genuinely critical, most will not, and the ranking is what makes the rest of the programme affordable. On most Canadian mid-market estates that handful is under ten. Then diligence gets proportionate. Deep on the few that matter, light and fast on the rest.

We test what a vendor claims rather than filing it.

Where a control matters, we ask for the artifact behind the answer, and where the vendor holds an attestation we read the exceptions rather than the cover page. The risk sits in two places. Contracts signed before anybody assessed anything, which is most legacy arrangements. And a register that stops at your direct suppliers while your actual exposure sits one layer further down.

What OSFI B-10 actually asks for.

The Canadian driver is specific. OSFI Guideline B-10, Third-Party Risk Management, was published 2023-04-30 and has been in effect since 2024-05-01. It reaches all federally regulated financial institutions, and it covers business and strategic arrangements broadly rather than outsourcing alone (source: OSFI, B-10). Two of its expectations get skipped almost universally: concentration risk "over multiple dimensions including geography, supplier", and the line that "the FRFI is responsible for identifying, monitoring and managing risk arising from subcontracting arrangements". If you are not federally regulated, this still reaches you through your customers' contracts.
Control checklist
THE METHOD

How our vendor risk assessment and vendor due diligence work runs.

Four steps, and step 01 is usually the one that surprises people. Nobody has a complete list. Procurement knows about the contracts, IT knows about the integrations, finance knows who gets paid, and the three lists disagree. We reconcile them before assessing anything, because a programme built on a partial inventory gives false comfort in exactly the places you have not looked.

  1. Step 01

    Reconcile the inventory

    Contracts, integrations and payments cross-checked into one list of who you actually rely on, including the ones nobody signed off.

  2. Step 02

    Rank by criticality

    What each third party touches, what breaks if it stops, and which ones justify deep diligence rather than a light check.

  3. Step 03

    Verify the critical few

    Artifacts rather than assertions, attestation exceptions read properly, and the fourth parties behind each critical vendor named.

  4. Step 04

    Fix the contracts and monitor

    Security, audit rights and continuity terms written in at renewal, plus a review cadence that survives without us.

QUESTIONS

Third party risk management questions, answered straight.

Answers first, including the one where we tell you your programme is already good enough. An architect takes the call.

Sometimes, and you have to read it to know. A report tells you an auditor tested described controls over a stated period, and the useful part is the exceptions section and the scope, not the opinion on page one. Check that the systems you rely on are actually in scope, that the period is current, and what the exceptions say. For a genuinely critical vendor we read the report and ask follow-up questions.

Directly, only if you're a federally regulated financial institution. It has been in effect since 2024-05-01 and covers business and strategic arrangements broadly, not just outsourcing. If you supply those institutions, it reaches you anyway through their contracts, which is why security schedules and audit rights started appearing in your renewals. We work out which side of that you're on before proposing anything.

You ask, in the contract, and then you verify the answer. B-10 makes the institution responsible for risk arising from subcontracting, so the right to know who your vendor uses belongs in the agreement rather than in a friendly email later. In practice we ask critical vendors to name the providers behind their service, check the concentration across your whole register, and flag where several of your critical suppliers turn out to sit on one platform.

They work as a filter and fail as assurance. A questionnaire is useful for sorting a long list quickly and for creating a written record of what a vendor asserted, which matters if something goes wrong later. What it cannot do is tell you whether the control exists, because nobody has checked. Use them to triage, then verify the few that matter with artifacts. Sending a 300-question form to every supplier is work that feels like diligence.

When you have fewer than a dozen suppliers and none of them touch customer data, because a short list and a careful read of two contracts is the whole job. When the real driver is one failed audit finding, which is cheaper to fix directly. And when procurement and IT still disagree about who your vendors are, since the inventory comes first and is worth buying on its own. We'd rather scope it down.

They're the usual weak spot, and they don't have to be renegotiated overnight. Canadian counsel reading B-10 in 2023 landed on the same expectation: legacy arrangements get reviewed and updated at the earliest appropriate renewal or revision point. So we rank them, work out which renewals are coming, and put the security, audit rights and continuity language into those first. The rest go on a dated plan you can show someone.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.